IPDebrief

51.68.107.146

IP Intelligence Dossier
Your IP: 216.73.216.123
{ } JSON πŸ”§ Full Actions API
πŸ€– Witness AIThis summary was generated by AI and may contain inaccuracies. Verify critical details independently.

# IP Intelligence Briefing: 51.68.107.146/32

Date: Analysis generated 2026-06-27

Subject: Network Threat Assessment

Classification: Moderate Risk

---

## Executive Summary

IP address 51.68.107.146 is a French-origin cloud infrastructure endpoint hosted on OVH SAS (ASN 16276) with a moderate risk score of 50. The IP is associated with DNS hostname crawl-9fxwvr.mj12bot.com and appears on two DNSBL listings. While no open services were detected, the address demonstrates persistent threat indicators and is part of a subnet with mixed abuse characteristics.

---

## Risk Profile

MetricValue
**Risk Score**50 (Moderate)
**Provider**OVH SAS (ASN 16276)
**Country**FR (France)
**Infrastructure**CloudCompute
**Operator Score**0.2609 (Basic)
**DNSBL Listings**2 of 8 total lists

The IP shows no Tor exit node activity, is not classified as a known attacker or spam source, and has no active threat campaigns associated.

---

## Network Context

Subnet Analysis (51.68.107.146/24):

The /24 subnet exhibits elevated activity with 12 active sibling IPs. Risk distribution across neighbors shows 10 medium-risk and 5 low-risk addresses, with no high-risk siblings detected. Notable neighbors include 51.68.107.138, 51.68.107.141, 51.68.107.148, 51.68.107.149, 51.68.107.150, 51.68.107.154, 51.68.107.156, 51.68.107.157, 51.68.107.159, and 51.68.107.161β€”all assigned risk scores of 50.

---

## DNS and Network Intelligence

Resolved Hostname: crawl-9fxwvr.mj12bot.com

Reverse DNS: Forward confirmed

Email Authentication: No SPF or DMARC records detected

The DNS association with "mj12bot.com" suggests potential web crawling or botnet infrastructure activity. The hostname pattern indicates automated systems rather than legitimate organizational infrastructure.

---

## Threat Timeline

Recent Observations:

The IP demonstrates persistent threat indicators with multiple blacklist listings within a 2-day window. Threat observation count stands at 1, with no persistent malicious activity flagged.

---

## Recommended Actions

Immediate Mitigation:

PlatformRule
iptables`iptables -A INPUT -s 51.68.107.146 -j DROP`
nftables`nft add rule inet filter input ip saddr 51.68.107.146 drop`
nginx`deny 51.68.107.146;`
pfSenseBlock 51.68.107.146/32
Cloudflare WAFBlock IP with expression `ip.src eq 51.68.107.146`
AWS WAFAdd 51.68.107.146/32 to blocklist

Additional Considerations:

---

## Intelligence Assessment

The IP address represents a moderate-risk cloud infrastructure endpoint with documented threat indicators including DNSBL listings and association with botnet-related hostname patterns. The subnet environment shows mixed abuse characteristics typical of shared cloud hosting providers. While no active service enumeration was detected, the DNS associations and blacklist presence warrant continued monitoring and recommended blocking at network perimeter controls.

Confidence Level: Moderate

Threat Severity: Medium

Action Priority: Medium

This summary was generated by AI and may contain inaccuracies. Verify critical details independently.

🌍 Geolocation

CountryπŸ‡«πŸ‡· France
Regionβ€”
Cityβ€”
TimezoneEurope/Paris
Latitude48.86
Longitude2.34

🏒 Ownership & Registration

OrganizationOVH SAS
ASNAS16276
Network Nameβ€”
CIDR Blockβ€”
RIRARIN
Countryβ€”
Abuse ContactAvailable via RDAP

🌐 DNS Intelligence

PTRcrawl-9fxwvr.mj12bot.com
Forward ConfirmedYes β€” FCrDNS verified
Forward Hostnamescrawl-9fxwvr.mj12bot.com

πŸ” DNS Hygiene

Hygiene Score40% (Fair)
SPFNot configured
DMARCNot configured
FCrDNSVerified
DNSSECValid
CAANot configured

☁️ Network Classification

InfrastructureInfrastructure / Datacenter
Service PurposeFirewalled / No Services
Network TierHosting β€” Infrastructure provider without advanced routing
CloudHosting

πŸ”Œ Services & Open Ports

PortServiceProtocolBanner
No open ports detected
Serverβ€”
HTTP Titleβ€”

πŸ” TLS Certificate

πŸ”’
No certificate
Issued by β€”
N/A
SANsNone
Valid Fromβ€”
Valid Untilβ€”

🎯 Confidence Breakdown

Per-dimension confidence scores based on source diversity and data freshness

DimensionScoreSourcesObservations
threat
38%
24
routing
13%
11
services
8%
11
ownership
24%
23
reputation
28%
13
geolocation
35%
23
Overall24%915
Coverage: 6/6 dimensions Β· Data sufficiency: sufficient
Data CoherenceConsistent (100%)
AttributionModerate (70%)
OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid

πŸ“… Observation Timeline πŸ”„ Live

First Seen2026-05-08 11:10:41 UTC
Last Seen2026-06-27 13:21:22 UTC
Profile Built2026-06-28 07:25:56 UTC
Data FreshnessLive
Signal Types20
Total Observations26
πŸ” 20 signal types Β· 26 observations collected
This report is generated from 20+ independent intelligence signals including ownership records, DNS analysis, BGP routing, TLS certificates, port scanning, threat feeds, behavioral fingerprinting, and more.
Full dossier details are available via our API.
{ } JSON API πŸ”§ Actions API πŸ“§ Enterprise Access

ℹ️ About This Report

All data shown is publicly available network metadata β€” IP addresses do not reliably identify individuals. Assessments are probabilistic and should not be used as sole basis for access control decisions. To report an issue or request data review, contact admin@ipdebrief.com.